PaloAltoNetworks / minemeld

Main MineMeld documentation repo
380 stars 64 forks source link

IOC's not making it to Output node #41

Open XiQshoner opened 5 years ago

XiQshoner commented 5 years ago

Recently I have noticed that some IOC's are not being classified into an Output miner. The logs show that the IOC is going through the motions and should eventually be added to the HighConfRed Output node but it continues to DROP_UPDATE. Please see the below log for a particularly dangerous IOC. Any help is appreciated.

image

jtschichold commented 5 years ago

Could you share the attributes of that specific IOC and the filters implemented on the output nodes? DROP_UPDATE means that the recvd IOC was reject by one of the infilters.